Dogfooding: use container scanning on GitLab omnibus

This page may contain information related to upcoming products, features and functionality. It is important to note that the information presented is for informational purposes only, so please do not rely on the information for purchasing or planning purposes. Just like with all projects, the items mentioned on the page are subject to change or delay, and the development, release, and timing of any products, features, or functionality remain at the sole discretion of GitLab Inc.

As mentioned in #9909 (closed), it would be great to utilize more Secure features when building GitLab's omnibus package. From the related issue:

  • omnibus should run container_scanning. Even if we check the dependencies with https://gitlab.com/gitlab-org/security-products/gitlab-depscan, it's only the first level deps. Clair will scan all the layers, so if a transient dep is installed, it could be spotted there.
Edited Sep 20, 2022 by 🤖 GitLab Bot 🤖
Assignee Loading
Time tracking Loading